Game theoretical framework for adaptive intrusion detection and response

Yuan-bo GUO,Jian-feng MA
DOI: https://doi.org/10.3321/j.issn:1001-506X.2005.05.040
2005-01-01
Abstract:A universal game model of perfect information between the attacker and the intrusion detection and response system is built to deal with the intrusion detection, response and countermeasure problem. On the basis of this model, the mixed strategy equilibriums and their properties are derived. Then, a comprehensive cost-benefit analysis of both players is given, thus enabling us to understand the relationships between alarm rate, response rate and punitive measure, and thus an adaptive intrusion response framework is designed. Finally, an extension of this model is also proposed and analyzed considering the inherent limitations of commercial intrusion detection and response systems.
What problem does this paper attempt to address?